URLhaus Database

You are currently viewing the URLhaus database entry for http://185.224.107.4:8580/tftp which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:2909290
URL: http://185.224.107.4:8580/tftp
URL Status:flame Online (spreading malware for 1 year, 11 month, 9 days, 9 hours, 2 minutes)
Host: 185.224.107.4
Date added:2024-06-27 18:50:15 UTC
Threat:Malware download Malware download
Reporter: NDA0E
Abuse complaint sent (?): Yes (2024-06-27 18:51:11 UTC to ipnoc{at}welcomeitalia[dot]it)
Tags:elf tftp

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-05-07n/aelf 829f76e09c6e3a92735fd324c0295e27cab04b8d4671d2eaa79c4579fe6b95c0Virustotal results 36.51% 
2025-04-24n/aelf ee0d9c4f826faa615c38634aaeee5d861fe5965396fe85d2c7de45c11a471fa3Virustotal results 28.57% 
2025-04-16n/aelf dbddaa26ccb0e2273bdd7453fcf45c0e633a6066117b853b8271fb5dd48af965n/a
2025-02-27n/aelf 049db4f64d8c7a311c8fa72e20795c5ca85eb7803d43dc2df16fbb892976fe3cVirustotal results 31.82% 
2024-12-20n/aelf df12b303824b9bcefb1ce78d1c30e6194a8ac870550957f9e45425122da5f99bVirustotal results 26.98% 
2024-12-04n/aelf d1fd00cc6382aef1c84d7adb297969a9a7c9f93dfc408a644dc9015274e2466en/a
2024-12-04n/aelf fb86b1ae70f7b067b400ad62b93e2bd2817d554ce22f2ca4c30535dcf2fd02abn/a 
2024-11-13n/aelf 321490c64d66511f750c3977ab2429d52806fbb30c7c160398b8f37bf3d621eeVirustotal results 23.08% 
2024-06-27n/aelf 9b66676da9413803e42cb2efda1bb76084cdf89d40f503a6716f4eb719ac972fVirustotal results 27.27%